Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Search Results: "rundll32.exe"
Click on any threat for detailed analysis and mitigation recommendations
Cisco Talos disclosed a complex WebDAV infection chain linked to a Russian threat actor (UAT-10820) targeting a Ukrainian government organization. The campaign delivers the Amatera stealer along with secondary payloads such as ZigCryptoStealer and NetSupport Manager. This operation appears opportunistic and broad-based, focusing on cryptocurrency and credential theft rather than a highly targeted attack. Attackers use creative delivery and evasion techniques, including abusing legitimate infrastructure like the BNB Smart Chain for bulletproof hosting and fake CAPTCHA prompts to bypass web filters. Secondary payloads include a vulnerable driver to terminate endpoint detection and response (EDR) software and unauthorized remote access tools, enabling persistent control over infected systems. Security teams are advised to monitor for unusual WebDAV activity and suspicious DLL execution via rundll32.exe ordinal calls, educate users about fake verification prompts, and ensure endpoint solutions have robust memory scanning capabilities. No patch information is provided for this threat. The disclosure also includes a broader discussion on cybersecurity workforce mental health but is unrelated to the technical threat. Join the discussion | Cisco Talos | 09/10/2026, 18:00:15 UTC Added: 09/10/2026, 18:03:59 UTC |
This analysis examines a sophisticated Vidar infostealer variant that employs a custom virtual machine to obfuscate its malicious code through proprietary bytecode interpretation. The malware implements extensive anti-analysis measures including debugger detection via NtQueryInformationProcess and RDTSC timing checks, sandbox evasion by identifying antivirus processes and checking system resources, and environment fingerprinting. Vidar targets credentials from web browsers including Chromium and Gecko-based extensions, Azure authentication tokens, FileZilla FTP credentials, and captures screenshots. It utilizes SeDebugPrivilege for elevated access, creates hidden desktops for browser automation, and exfiltrates stolen data through Telegram channels. The malware performs cleanup operations to remove execution artifacts and proxies DLL execution through rundll32.exe to blend with legitimate Windows processes. Join the discussion | AlienVault OTX General | 09/09/2026, 06:38:56 UTC Added: 09/09/2026, 10:51:59 UTC |
A sophisticated ClickFix campaign variant uses social engineering to trick victims into executing commands via the Windows Run dialog. The technique leverages rundll32.exe to load remote non-DLL payloads by ordinal export #1 over WebDAV connections tunneled through HTTPS port 443. Multiple incidents at a single organization show evolving obfuscation methods including WMI process spawning, caret insertion, and runtime string assembly to evade detection. The attack chain utilizes trusted Windows binaries like pcalua.exe to break process lineage tracking. No files are dropped to disk, and payloads are invoked by ordinal rather than named functions. Successful attacks exfiltrated browser credentials and sensitive documents totaling 13MB. The most obfuscated variant evaded automated EDR detection entirely, being discovered only through proactive threat hunting focused on ordinal execution patterns rather than keyword detection. Join the discussion | AlienVault OTX General | 07/29/2026, 02:59:33 UTC Added: 07/29/2026, 12:07:07 UTC |
Punto Switcher through 4.5.0.583 contains an unquoted search path element vulnerability that allows local attackers to execute arbitrary code by exploiting the application's call to WinExec without a fully qualified path for RunDll32.exe when invoking shell32.dll Control_RunDLL input.dll. Attackers can place a malicious executable earlier in the search order to achieve arbitrary code execution in the context of the affected user. Join the discussion | CVE Database V5 | 06/18/2026, 19:39:14 UTC Added: 06/18/2026, 19:51:23 UTC |
The Chinese APT group Silver Fox has launched an SEO poisoning campaign targeting Chinese-speaking users, impersonating Microsoft Teams. The campaign uses a modified ValleyRAT loader with Cyrillic elements to mislead attribution. Silver Fox aims to conduct espionage and financial fraud, posing a significant threat due to its dual mission. The attack chain involves a fake Teams website, malicious ZIP files, and binary data retrieval from XML and JSON files. The malware exploits rundll32.exe for binary proxy execution and establishes C2 communication. Attribution to Silver Fox is based on overlapping infrastructure and links to previous campaigns. Organizations with global operations, especially in China, are advised to implement robust security measures and logging capabilities to defend against this evolving threat. Join the discussion | AlienVault OTX General | 12/10/2025, 17:22:42 UTC Added: 12/11/2025, 09:08:56 UTC |
Remote Keyboard Desktop 1.0.1 enables remote attackers to execute system commands via the rundll32.exe exported function export, allowing unauthenticated code execution. Join the discussion | CVE Database V5 | 12/04/2025, 20:46:33 UTC Added: 12/04/2025, 20:53:51 UTC |
A new campaign is distributing the Oyster (Broomstick) backdoor through trojanized Microsoft Teams installers. Threat actors are using SEO poisoning and malvertising to trick users into downloading fake installers from spoofed websites. The malicious installers deploy a persistent backdoor that enables remote access, gathers system information, and supports additional payload delivery while evading detection. This tactic mirrors earlier fake PuTTY campaigns, showing a trend of abusing trusted software for initial access. The backdoor communicates with attacker-controlled C2 domains and uses DLL sideloading via rundll32.exe for stealthy execution. Organizations are advised to download software only from verified sources and avoid relying on search engine advertisements. Join the discussion | AlienVault OTX General | 10/02/2025, 10:24:47 UTC Added: 10/02/2025, 10:27:46 UTC |
Showing 1 to 7 of 7 results